Professional Documents
Culture Documents
protected functions: is only valid to say that a failure will have nonit operational consequences because a stand-by or redundant component is available if it is reasonable to assume that the protective device will be functional when the failure occLIrs. This of course means that a suitable maintenance program must be applied to the protective device (the stand-by pump in the example given above). This issue is discussed at length in the next part of this chapter. If the consequences of the multiplc failure of a protected system are particul;trly serious, it rnay be worth trying to prevent the failure of the protected function as well as the protective device in order to reduce the probability of the multiple failure to a tolerable level. (As explained on Page 97, if the rni~ltiple failure has safety consequences, it may be wise to assess consequences as if the protection was not present at all, and then to revalidate the protection as part of the task selection process.)
The existence of such a system creates two sets of failure possibilities, depending on whether the protective device is fail-safe or not. We consider the implications of each set in the following paragraphs, starting with devices which are fail-safe. Fuil-saje protective devices In this context, fail-safe means that the failure of the device o n its o w n will nor~nal circtrnixtances become evident to the operating crew ~lnder
Zrz the context of this hook, a 'fail-safe' device is one whose failure on its own will become evident to the operating crew under norrnal circurnstances